Frame Injection Vulnerability in Firefox 1.0.4 - again

Firefox, Thunderbird, SeaMonkey, Camino, Mozilla, Netscape 6/7/8/9, and all Gecko-based browsers discussion and support forum.
(MozInfo701, Netscape Browser Archive)

Moderators: Antony, Edward, profman, Ramona

Postby Ramona » Tue 07 Jun, 2005 7:31 pm

akbash wrote:I'm not entirely certain this works in all cases, but Secunia's testcase fails if you have Firefox set to open new windows in tabs.


My findings exactly. I thought perhaps I must be doing something wrong, but evidently it was something right!

Ramona
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4 (ax)
User avatar
Ramona
Moderator
Moderator
 
Posts: 2376
Joined: Wed 19 Jun, 2002 3:50 pm
Location: Midwest USA

Postby Don_HH2K » Tue 07 Jun, 2005 7:58 pm

I'm not aware that Mozilla 1.7.8 has a UI for the appropriate pref (as Firefox does), but it is interesting to note that setting the pref [tt]browser.tabs.opentabfor.windowopen[/tt] to true does not have an effect, and therefore does not bypass this bug in Mozilla.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8) Gecko/20050511 Donzilla/0.7PR2 (WML/1.3; WML/1.2; WML/1.1; WML/1.0)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Re: Netscape 8 whith IE 6 engine

Postby Betuaelmon » Wed 08 Jun, 2005 1:56 pm

dluchini30 wrote:
Betuaelmon wrote:If you use NS 8 with IE 6 engine whitout SP has got the same vulnerability as
Firefox 1.0.4, but with IE 6 SP 2 all is ok. True or false?


False. This depends on a lot of things.

First of all, if you use the Firefox rendering engine in Netscape 8, you are subject to this vulnerability. If you use IE6, you aren't, because IE isn't affected by this vulnerability. BUT, then you expose yourself to the world of IE vulnerabilities again, so leaving yourself open to this frame injection bug is the lesser of all evils.


Thank you very much for your answer :)
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20050519 Netscape/8.0.1
Betuaelmon
junior member
junior member
 
Posts: 7
Joined: Mon 06 Jun, 2005 4:07 pm

Postby Edward » Sun 12 Jun, 2005 6:39 am

Any word yet on when this issue will be taken care or (presumably in a version 1.0.5)?
UserAgent: Mozilla/5.0 (X11; U; Linux i586; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4
SillyDog701 Moderator
debian 6 - iceape - iceweasel - icedove - seamonkey
User avatar
Edward
Moderator
Moderator
 
Posts: 3584
Joined: Sun 01 Dec, 2002 7:15 pm

Postby akbash » Sun 12 Jun, 2005 11:46 am

It's been fixed in the nightly builds since last Wednesday. I couldn't say when the next official release is scheduled.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8b2) Gecko/20050530 Firefox/1.0+
akbash
silver member
silver member
 
Posts: 364
Joined: Mon 09 Feb, 2004 9:13 pm

Previous

Return to Firefox, SeaMonkey and Netscape

Who is online

Registered users: beanboy89, Google [Bot]